Core Contracts

Regnum Aurum Acquisition Corp
HardhatReal World AssetsNFT
77,280 USDC
View results
Submission Details
Severity: high
Valid

Token Get Stuck in RACCNFT Contract

Summary

Token used to mint the RACCNFT cannot be withdrawn.

Vulnerability Details

There is no way to allow the owner/seller of the RACCNFT in https://github.com/Cyfrin/2025-02-raac/blob/main/contracts/core/tokens/RAACNFT.sol to withdraw his Money. There is no function to get the money out of the contract which will result to the money get stucked in the contract.

Impact

The token used to pay for Buying the RACCNFT will get stuck in the RACCNFT contract.

Tools Used

manual review

Recommendations

It is advisable to add withdrawal function to withdraw the token for the seller/Owner of the RACCNFT.

Updates

Lead Judging Commences

inallhonesty Lead Judge 4 months ago
Submission Judgement Published
Validated
Assigned finding tags:

RAACNFT collects payment for NFT minting but lacks withdrawal functionality, permanently locking all tokens in the contract

inallhonesty Lead Judge 4 months ago
Submission Judgement Published
Validated
Assigned finding tags:

RAACNFT collects payment for NFT minting but lacks withdrawal functionality, permanently locking all tokens in the contract

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.